Need to configure audit logging in Solaris but I have a problem. There are two SunOS servers which were configured before. When I started analysing logs I found out that in Solaris 10 I can see the name of user who login/logout but in Solaris 11 not. Solaris 10 audit event example:
May 13 10:58:46 server audit: [ID 702911 audit.notice] login - ssh ok session 1722469439 by username as username:group from pc1.my.domain
May 13 10:59:10 server audit: [ID 702911 audit.notice] logout ok session 1722469439 by username as username:group from pc1.my.domain
Solaris 11 example for the same user:
May 13 10:59:53 server audit: [ID 702911 audit.notice] login - ssh ok in global
May 13 11:00:13 server audit: [ID 702911 audit.notice] logout ok in global
Reading Solaris 11 audit concepts pages didn't give me an answer. In both cases /etc/security/audit_event files look the same. I've only checked out that they contain:
6152:AUE_login:login - local:lo
6153:AUE_logout:logout:lo
Could someone please give me an advice what else needs to be checked?